SlowMist Warns of Large-Scale npm Supply-Chain Attack on Keyv/Cacheable Ecosystem

SlowMist Warns of Large-Scale npm Supply-Chain Attack on Keyv/Cacheable Ecosystem

N
News Editor
2026-08-05 03:52:02
SlowMist disclosed on August 5 that it has detected a large-scale npm supply-chain attack affecting the Keyv/Cacheable ecosystem. Attackers have published more than 2,000 malicious package versions, including keyv@6.0.0. Keyv is a widely used key-value storage abstraction layer supporting Redis, SQLite, PostgreSQL, MongoDB and other backends, with roughly 127 million weekly downloads, creating potentially broad downstream supply-chain risk. The attack closely resembles the Shai-Hulud npm worm campaign, indicating strong automation and self-propagation. Potential malicious behaviors include credential theft, environment variable exfiltration, CI/CD secret leakage, remote payload delivery, and lateral movement through compromised development environments. SlowMist recommends security teams immediately identify and remove affected versions, upgrade to verified safe versions, review dependency lock files and build logs, monitor anomalous outbound connections, rotate potentially exposed credentials, and rebuild environments from trusted sources if compromise is suspected.
SlowMist disclosed on August 5 that it detected a large-scale npm supply-chain attack affecting the Keyv/Cacheable ecosystem. Attackers have released more than 2,000 malicious package versions into the ecosystem, including keyv@6.0.0. Keyv is a widely used key-value storage abstraction layer that supports backends including Redis, SQLite, PostgreSQL, and MongoDB. The package records roughly 127 million weekly downloads, a footprint SlowMist said could translate into broad downstream supply-chain risk.

Attack Profile

The attack method closely resembles the earlier Shai-Hulud npm worm campaign, according to SlowMist. The resemblance points to a high degree of automation and self-propagation behind the operation. Potential malicious behavior includes credential theft, exfiltration of environment variables, leakage of CI/CD secrets, remote payload delivery, and lateral movement through infected development environments.

Recommended Actions

SlowMist urged security teams to immediately identify and remove affected versions, upgrade to verified safe versions, revisit dependency lock files and build logs, monitor suspicious outbound connections, and rotate any credentials that may have been exposed. If an environment is suspected to be compromised, teams should rebuild it from trusted sources.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
550

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.